MIT licensing is clear, releases are frequent, and the source project has tests and a security policy. Its low popularity provides little independent evidence for a security-focused dependency.
45%
Total Score
75
100
81
100
The repository name does not match the package name and its README does not mention the package. Together with the README describing Epicrypt, this makes the repository linkage and package provenance unclear.
The artifact includes a substantial README, while the repository has tests; the missing artifact changelog and tests are normal packaging choices. However, the README describes a different project, which weakens its consumer documentation value.
The linked repository is owned by an organization, which provides some continuity and handoff capacity. That support does not resolve the package-to-repository identity mismatch.
One contributor made all 353 commits in the last three months, leaving no demonstrated backup maintainer. Organization ownership offers some handoff capacity, but no second active contributor is shown.
The audit covered both workflows with no untrusted checkout, injection, or high-confidence findings, and permissions are scoped or read-only. However, all 18 action references are unpinned, leaving workflow dependencies exposed to moving upstream code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
phpseclib/phpseclib Version ^4.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.